Web Hack List

Collected research

[EN] Multi-sandwich attack with MongoDB Object ID or the scenario for real-time monitoring of web application invitations: a new use case for the sandwich attack

MongoDB ObjectIDs used as invitation tokens carry a second-resolution timestamp, a process value and an incrementing counter, so a token minted for someone else lies inside the rectangle bounded by two tokens the attacker mints himself. Bracketing with 10-second windows instead of one long one cuts candidates from 1.16 million to a few hundred, and a counter that jumps by more than one between consecutive attacker tokens flags exactly which window to brute-force.

Record

Published by
aeth.cc
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of aeth.cc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .